Aravind Srinivas:我们的安全团队上个月花时间试图攻破 SPACE,这是运行 Perplexity Computer 全部内容的沙箱平台。我…
我们的安全团队上个月花时间试图攻破 SPACE,这是运行 Perplexity Computer 全部内容的沙箱平台。我们为 9 个模型(Opus 5、GPT-5.6 Sol、Kimi K3、Gemini 3.1 Pro 等)在虚拟机内授予了 root 访问权限;在某些运行中,还提供了完整的沙箱源代码。我们要求它们要么逃逸到主机,要么访问我们的网络策略所阻止的 URL。
在 108 次运行中,没有一个模型逃出虚拟机。
但一旦我们允许少量网络访问(仅 PyPI 和 Ubuntu 镜像,以便它们安装软件包),4 个模型成功访问了被阻止的 URL,方法如下:
- 伪造对我们网关的 DNS 响应,并利用 http://pypi.org 位于与数千其他网站共享的 Fastly IP 这一事实。
- GPT-5.6 Cyber 通过 Taboola 的图像获取器访问截图服务,然后从图像中使用 OCR 提取出标志。
我们修复了这两个问题,并确保重跑结果稳定。我们还测试了另外 10 个沙箱提供商,其中 8 个存在相同的 IP 共享问题,例如 E2B、Vercel、Modal。
公开分享红队测试研究是行业构建防护栏的最佳方式,我们期待与 @nvidia 合作,将这些防护栏纳入他们今天宣布的 Open Agent Safety Platform。
对照原文
Our security team spent the last month trying to break SPACE, the sandbox platform that runs all of Perplexity Computer. We gave 9 models (Opus 5, GPT-5.6 Sol, Kimi K3, Gemini 3.1 Pro, etc.) root access inside the VM; in some runs, the full sandbox source code too. We asked them to either escape to the host or reach a URL our network policy blocks. None of them got out of the VM in 108 runs. But once we allowed a bit of network access (just PyPI and Ubuntu mirrors so that they could install packages), 4 models managed to reach the blocked URL by: 1. Spoofing DNS responses to our gateway and using the fact that https://t.co/UtoIWyj1yj sits on a Fastly IP shared with thousands of other sites. 2. GPT-5.6 Cyber went through Taboola's image fetcher to a screenshot service and then OCR'd the flag out of the image. We fixed both issues and made sure the reruns held. We also tested 10 other sandbox providers, and 8 of them had the same IP-sharing problem, eg E2B, Vercel, Modal. Openly sharing the red teaming research is the best way to build guardrails as an industry, and we look forward to working together with @nvidia to incorporate the guardrails into their Open Agent Safety Platform announced today. https://t.co/AJ97iFK3XS